fix(backups): rbac actualized (#2145)
<!-- Thank you for making a contribution! Here are some tips for you: - Start the PR title with the [label] of Cozystack component: - For system components: [platform], [system], [linstor], [cilium], [kube-ovn], [dashboard], [cluster-api], etc. - For managed apps: [apps], [tenant], [kubernetes], [postgres], [virtual-machine] etc. - For development and maintenance: [tests], [ci], [docs], [maintenance]. - If it's a work in progress, consider creating this PR as a draft. - Don't hesistate to ask for opinion and review in the community chats, even if it's still a draft. - Add the label `backport` if it's a bugfix that needs to be backported to a previous version. --> ## What this PR does ### Release note <!-- Write a release note: - Explain what has changed internally and for users. - Start with the same [label] as in the PR title - Follow the guidelines at https://github.com/kubernetes/community/blob/master/contributors/guide/release-notes.md. --> ```release-note - fixed rbac for backup controllers ``` <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated backup controller permissions to focus on core backup operations. * Expanded backup strategy controller permissions to support enhanced backup and restore capabilities, including Velero integration and status management. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
This commit is contained in:
commit
1429b94f5d
2 changed files with 29 additions and 20 deletions
|
|
@ -3,30 +3,14 @@ apiVersion: rbac.authorization.k8s.io/v1
|
|||
metadata:
|
||||
name: backups.cozystack.io:core-controller
|
||||
rules:
|
||||
# Plan: reconcile schedule and update status
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["plans"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backupjobs"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "patch"]
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backupjobs/status"]
|
||||
resources: ["plans/status"]
|
||||
verbs: ["get", "update", "patch"]
|
||||
# BackupJob: create when schedule fires (status is updated by backupstrategy-controller)
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backups"]
|
||||
resources: ["backupjobs"]
|
||||
verbs: ["create", "get", "list", "watch"]
|
||||
- apiGroups: ["apps.cozystack.io"]
|
||||
resources: ["buckets", "bucketaccesses", "virtualmachines"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["objectstorage.k8s.io"]
|
||||
resources: ["buckets", "bucketaccesses"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: [""]
|
||||
resources: ["secrets"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "patch"]
|
||||
- apiGroups: ["kubevirt.io"]
|
||||
resources: ["virtualmachines"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["velero.io"]
|
||||
resources: ["backups", "backupstoragelocations", "volumesnapshotlocations", "restores"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "patch"]
|
||||
|
|
|
|||
|
|
@ -3,9 +3,34 @@ apiVersion: rbac.authorization.k8s.io/v1
|
|||
metadata:
|
||||
name: backups.cozystack.io:strategy-controller
|
||||
rules:
|
||||
# Strategy types (Velero, Job)
|
||||
- apiGroups: ["strategy.backups.cozystack.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
# BackupClass: resolve strategy per application
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backupclasses"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
# BackupJob / RestoreJob: reconcile and update status
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backupjobs", "restorejobs"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backupjobs/status", "restorejobs/status"]
|
||||
verbs: ["get", "update", "patch"]
|
||||
# Backup: create after Velero backup completes
|
||||
- apiGroups: ["backups.cozystack.io"]
|
||||
resources: ["backups"]
|
||||
verbs: ["create", "get", "list", "watch"]
|
||||
# Application refs (e.g. VMInstance, VirtualMachine) for backup/restore scope
|
||||
- apiGroups: ["apps.cozystack.io"]
|
||||
resources: ["*"]
|
||||
verbs: ["get", "list", "watch"]
|
||||
# Velero Backup/Restore in cozy-velero namespace
|
||||
- apiGroups: ["velero.io"]
|
||||
resources: ["backups", "restores"]
|
||||
verbs: ["create", "get", "list", "watch", "update", "patch"]
|
||||
# Leader election (--leader-elect)
|
||||
- apiGroups: ["coordination.k8s.io"]
|
||||
resources: ["leases"]
|
||||
verbs: ["get", "list", "watch", "create", "update", "patch"]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue